Executive brief
A vulnerability in the Autofill feature of Google Chrome for iOS could allow a malicious website to access data from other websites. This occurs when the browser incorrectly handles data entry policies, potentially leading to the exposure of sensitive user information. Users are advised to update to the latest version of Chrome to prevent unauthorized data access.
Technical details
A policy enforcement vulnerability exists in the Autofill component of Google Chrome for iOS. The flaw allows a remote attacker to bypass cross-origin restrictions by enticing a user to visit a specially crafted HTML page. By exploiting this insufficient enforcement, the attacker can leak sensitive data across origins that should otherwise be isolated. This issue is resolved in version 149.0.7827.53. The vulnerability was assigned a 'High' severity rating by the Chromium project.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: NVD publication date